CVE-2026-78037
8.8Xiiaozet · Xiiaozet LK100W
The Xiiaozet LK100W web-based management interface is susceptible to OS command injection, allowing authenticated attackers to execute arbitrary commands on the underlying operating system.
Executive summary
An OS command injection vulnerability in the Xiiaozet LK100W management interface allows authenticated attackers to gain elevated privileges and potentially achieve full device compromise.
Vulnerability
This flaw is an OS command injection (CWE-78) occurring within the web-based management interface. It requires the attacker to have authenticated access to the interface to trigger the execution of arbitrary system commands.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational operations, as it grants an attacker the ability to execute unauthorized commands with elevated privileges. This could lead to a complete compromise of the affected device, resulting in unauthorized access to sensitive operational data, potential disruption of critical services, or the use of the device as a pivot point within the network. The CVSS score of 8.8 reflects the high risk associated with the potential for full system control.
Remediation
Immediate Action: Update the Xiiaozet LK100W firmware to version 2.1.240 or later to remediate the command injection flaw.
Proactive Monitoring: Review device access logs for suspicious administrative activity or unusual command patterns originating from authenticated user sessions.
Compensating Controls: Implement strict network segmentation and restrict access to the web-based management interface to authorized personnel only, ideally through a VPN or internal management VLAN.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for complete device compromise, it is imperative that administrators prioritize the firmware update to version 2.1.240. Organizations should verify that only trusted users have access to the web-based management interface to minimize the attack surface until the update is applied. Failure to remediate this vulnerability leaves critical infrastructure susceptible to unauthorized remote control.
More Xiiaozet CVEs
Sources
Originally found and disclosed by Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA., per the CVE Program record.